Adobe Acrobat vulnerabilities
1,379 known vulnerabilities affecting adobe/acrobat.
Total CVEs
1,379
CISA KEV
24
actively exploited
Public exploits
46
Exploited in wild
41
Severity breakdown
CRITICAL538HIGH495MEDIUM320LOW26
Vulnerabilities
Page 67 of 69
CVE-2004-1598P4MEDIUMCVSS 5.0v6.0v6.0.1+1 more2004-10-12
CVE-2004-1598 [MEDIUM] CVE-2004-1598: Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file t
Adobe Acrobat and Acrobat Reader 6.0 allow remote attackers to read arbitrary files via a PDF file that contains an embedded Shockwave (swf) file that references files outside of the temporary directory.
nvd
CVE-2024-20721P4MEDIUMCVSS 5.5≤ 120.0.2210.912024-01-15
CVE-2024-20721 [MEDIUM] CWE-20 CVE-2024-20721: Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input V
Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2024-20709P4MEDIUMCVSS 5.5≤ 120.0.2210.912024-01-15
CVE-2024-20709 [MEDIUM] CWE-20 CVE-2024-20709: Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input V
Acrobat Reader T5 (MSFT Edge) versions 120.0.2210.91 and earlier are affected by an Improper Input Validation vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a mal
nvd
CVE-2021-39857P4MEDIUMCVSS 4.3≥ 17.011.30059, ≤ 17.011.30199≥ 20.001.30005, ≤ 20.004.300062021-09-29
CVE-2021-39857 [MEDIUM] CWE-200 CVE-2021-39857: Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004
Adobe Acrobat Reader DC add-on for Internet Explorer versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to check for existence of local files. Exploitation of this issue requires use
nvd
CVE-2021-44702P4MEDIUMCVSS 4.3≥ 20.001.30005, ≤ 20.004.30017≥ 17.011.30180, ≤ 17.011.302042022-01-14
CVE-2021-44702 [MEDIUM] CWE-200 CVE-2021-44702: Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) an
Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim mus
nvd
CVE-2011-0562P4MEDIUMCVSS 6.9v8.0v8.1+26 more2011-02-10
CVE-2011-0562 [MEDIUM] CVE-2011-0562: Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2
Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2011-0570 and CVE-2011-0588.
nvd
CVE-2026-47925P4MEDIUMCVSS 5.5≥ 24.0.0, < 24.001.303832026-06-09
CVE-2026-47925 [MEDIUM] CWE-190 CVE-2026-47925: Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow o
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in
nvd
CVE-2011-0604P4MEDIUMCVSS 4.3v8.0v8.1+26 more2011-02-10
CVE-2011-0604 [MEDIUM] CVE-2011-0604: Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0587.
nvd
CVE-2011-0587P4MEDIUMCVSS 4.3v8.0v8.1+26 more2011-02-10
CVE-2011-0587 [MEDIUM] CWE-79 CVE-2011-0587: Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before
Cross-site scripting (XSS) vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows and Mac OS X allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2011-0604.
nvd
CVE-2021-21060P4MEDIUMCVSS 4.6≥ 17.0, ≤ 17.011.30188≥ 20.0, ≤ 20.001.300182021-02-11
CVE-2021-21060 [MEDIUM] CWE-20 CVE-2021-21060: Adobe Acrobat Pro DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.01
Adobe Acrobat Pro DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an improper input validation vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive information in the context of the current user. Exploitation of this issue requires us
nvd
CVE-2011-2100P4MEDIUMCVSS 6.9v8.0v8.1+34 more2011-06-16
CVE-2011-2100 [MEDIUM] CVE-2011-2100: Untrusted search path vulnerability in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, an
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory.
nvd
CVE-2011-0570P4MEDIUMCVSS 6.9v8.0v8.1+26 more2011-02-10
CVE-2011-0570 [MEDIUM] CVE-2011-0570: Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2
Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2011-0562 and CVE-2011-0588.
nvd
CVE-2011-0588P4MEDIUMCVSS 6.9v8.0v8.1+26 more2011-02-10
CVE-2011-0588 [MEDIUM] CVE-2011-0588: Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2
Untrusted search path vulnerability in Adobe Reader and Acrobat 10.x before 10.0.1, 9.x before 9.4.2, and 8.x before 8.2.6 on Windows allows local users to gain privileges via a Trojan horse DLL in the current working directory, a different vulnerability than CVE-2011-0562 and CVE-2011-0570.
nvd
CVE-2022-28252P4LOWCVSS 3.3≥ 17.011.30059, ≤ 17.012.30205≥ 20.001.30005, ≤ 20.005.30314+1 more2022-05-11
CVE-2022-28252 [LOW] CWE-125 CVE-2022-28252: Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (a
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exp
nvd
CVE-2007-5666P4MEDIUMCVSS 6.2≤ 8.1.12008-02-12
CVE-2007-5666 [MEDIUM] CWE-94 CVE-2007-5666: Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users
Untrusted search path vulnerability in Adobe Reader and Acrobat 8.1.1 and earlier allows local users to execute arbitrary code via a malicious Security Provider library in the reader's current working directory. NOTE: this issue might be subsumed by CVE-2008-0655.
nvd
CVE-2010-3656P4MEDIUMCVSS 4.3v8.0v8.1+23 more2010-10-06
CVE-2010-3656 [MEDIUM] CVE-2010-3656: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3657.
nvd
CVE-2010-3657P4MEDIUMCVSS 4.3v8.0v8.1+23 more2010-10-06
CVE-2010-3657 [MEDIUM] CVE-2010-3657: Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Window
Unspecified vulnerability in Adobe Reader and Acrobat 9.x before 9.4, and 8.x before 8.2.5 on Windows and Mac OS X, allows attackers to cause a denial of service via unknown vectors, a different vulnerability than CVE-2010-3656.
nvd
CVE-2011-2104P4MEDIUMCVSS 4.3v8.0v8.1+34 more2011-06-16
CVE-2011-2104 [MEDIUM] CWE-119 CVE-2011-2104: Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac O
Adobe Reader and Acrobat 8.x before 8.3, 9.x before 9.4.5, and 10.x before 10.1 on Windows and Mac OS X allow attackers to cause a denial of service (memory corruption) via unspecified vectors.
nvd
CVE-2024-49531P4MEDIUMCVSS 5.5≥ 20.001.30002, < 20.005.30748≥ 24.001.30159, < 24.001.302252024-12-10
CVE-2024-49531 [MEDIUM] CWE-476 CVE-2024-49531: Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and ear
Acrobat Reader versions 24.005.20307, 24.001.30213, 24.001.30193, 20.005.30730, 20.005.30710 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this
nvd
CVE-2008-4816P4MEDIUMCVSS 4.3≤ 8.1.2v8.1.12008-11-05
CVE-2008-4816 [MEDIUM] CVE-2008-4816: Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allow
Unspecified vulnerability in the Download Manager in Adobe Reader 8.1.2 and earlier on Windows allows remote attackers to change Internet Security options on a client machine via unknown vectors.
nvd